Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 205

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
voice message by recording in question area
Nearly a thousand Google workers sign letter urging company to divest from ICE, CBP
Berkshire Hathaway outperforms this week as tech stocks sink
I've studied over 200 kids—the happiest ones have parents who do 6 things with them before bedtime
Pressure mounts on American Airlines CEO as carrier lags rivals
Super Bowl 60: Movie trailers and AI dominate ads; Bad Bunny halftime ahead
U.S. plans initial payment towards billions owed to the UN, envoy Waltz says
Japanese Prime Minister Takaichi's ruling LDP set to secure supermajority in Lower House: NHK
Goldman Sachs says this under-the-radar biotech play could more than double in value
Stock futures tick higher as Wall Street awaits closely watched jobs, inflation reports: Live updates